Decode NetBIOS Name

Category: Ciphers

Status: Registered and callable in the CyberChef 11.3.0 compatibility inventory.

Input / output: byteArray → byteArray

Background: https://wikipedia.org/wiki/NetBIOS

What it does

NetBIOS names as seen across the client interface to NetBIOS are exactly 16 bytes long. Within the NetBIOS-over-TCP protocols, a longer representation is used. There are two levels of encoding. The first level maps a NetBIOS name into a domain system name. The second level maps the domain system name into the ‘compressed’ representation required for interaction with the domain name system. This operation decodes the first level of encoding. See RFC 1001 for full details.

Note

Status here means the operation name is implemented and callable. It does not by itself promise byte-for-byte parity for every upstream option. See Compatibility and current status for the verified scope and known boundaries.

Arguments and options

Arguments are positional. Keep their order when using bake() or Pipeline.then().

Index

Name

UI type

PyChef default

Accepted values / format

0

Offset

number

65

A Python integer or floating-point value

Recipe template

Important

This is a call template built from the documented defaults. Replace placeholder values such as empty keys, paths, patterns, or lookup data before running it.

from pychef import bake

input_value = b"example"
args = [65]
result = bake(input_value, [{"op": 'Decode NetBIOS Name', "args": args}])
print(result)

Pipeline example

from pychef import Pipeline

args = [65]
transform = Pipeline().then('Decode NetBIOS Name', *args)
result = transform(b"example")

Dedicated operation module

The registered entry point lives in pychef.operations.by_operation.decode_netbios_name. Direct calls receive the input value and a positional argument tuple:

from pychef.operations.by_operation.decode_netbios_name import run

result = run(b"example", tuple([65]))
pychef.operations.by_operation.decode_netbios_name.run(value, args)

Run this operation using its shared internal implementation.

Parameters:
  • value (str | bytes)

  • args (Sequence[Any])

Return type:

str | bytes